CWE-73 · 573 kayıt
External Control of File Name or Path
Bu sınıftaki CVE’ler
574 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2025-33053Silahlaştırılmış | Internet Shortcut Files Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-73 | Yüksek8,8 | KEV | %87,0 | 10 Haz 2025 |
81Hemen | CVE-2024-43451Silahlaştırılmış | NTLM Hash Disclosure Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-73 | Orta6,5 | KEV | %84,1 | 12 Kas 2024 |
69Bu hafta | CVE-2022-39952Silahlaştırılmış | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,fortinet · fortinac · CWE-73 | Kritik9,8 | — | %99,8 | 16 Şub 2023 |
69Bu hafta | CVE-2025-24054Silahlaştırılmış | NTLM Hash Disclosure Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-73 | Orta5,4 | KEV | %58,9 | 11 Mar 2025 |
67Bu hafta | CVE-2024-8517Silahlaştırılmış | SPIP Bigup Multipart File Upload OS Command Injectionspip · spip · CWE-73 | Kritik9,8 | — | %94,6 | 6 Eyl 2024 |
65Bu hafta | CVE-2023-4634Kavram kanıtı | Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Executiondavidlingren · media library assistant · CWE-73 | Kritik9,8 | — | %85,6 | 6 Eyl 2023 |
64Bu hafta | CVE-2018-17246Kavram kanıtı | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.elastic · kibana · CWE-73 | Kritik9,8 | — | %82,3 | 20 Ara 2018 |
62Bu hafta | CVE-2023-3643Kavram kanıtı | Boss Mini document file inclusioncarel · boss mini firmware · CWE-73 | Kritik9,8 | — | %75,4 | 12 Tem 2023 |
59Planlayın | CVE-2025-0111Silahlaştırılmış | PAN-OS: Authenticated File Read Vulnerability in the Management Web Interfacepaloaltonetworks · pan-os · CWE-73 | Yüksek7,1 | KEV | %2,0 | 12 Şub 2025 |
46Planlayın | CVE-2021-27250İstismar yok | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc0dlink · dap-2020 firmware · CWE-73 | Orta6,5 | — | %67,4 | 14 Nis 2021 |
44Planlayın | CVE-2021-21343İstismar yok | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rightsxstream · xstream · CWE-73 | Yüksek7,5 | — | %46,7 | 22 Mar 2021 |
41Planlayın | CVE-2024-37149İstismar yok | GLPI allows remote code execution through the plugin loaderglpi-project · glpi · CWE-73 | Yüksek8,8 | — | %21,1 | 10 Tem 2024 |
41Planlayın | CVE-2024-0265İstismar yok | SourceCodester Clinic Queuing System GET Parameter index.php file inclusionoretnom23 · clinic queuing system · CWE-73 | Yüksek8,8 | — | %20,9 | 7 Oca 2024 |
41Planlayın | CVE-2024-0087İstismar yok | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.nvidia · triton inference server · CWE-73 | Yüksek8,8 | — | %19,9 | 14 May 2024 |
40Planlayın | CVE-2025-71338Kavram kanıtı | Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store APIflowiseai · flowise · CWE-73 | Kritik10,0 | — | %1,2 | 25 Haz 2026 |
40Planlayın | CVE-2025-54945İstismar yok | SUNNET Corporate Training Management System - External Control of File Name or Pathsun.net · ehrd ctms · CWE-73 | Kritik10,0 | — | %0,5 | 30 Ağu 2025 |
40Planlayın | CVE-2026-20358İstismar yok | Cisco Crosswork Security Hardening Release: August 2026cisco · cisco crosswork planning · CWE-73 | Kritik10,0 | — | %0,5 | 19 Ağu 2026 |
39İzleyin | CVE-2025-6463İstismar yok | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submissincsub · forminator · CWE-73 | Yüksek8,8 | — | %12,7 | 2 Tem 2025 |
39İzleyin | CVE-2019-3681İstismar yok | osc: stores downloaded (supposed) RPM in network-controlled filesystem pathssuse · linux enterprise server · CWE-73 | Kritik9,8 | — | %1,4 | 29 Haz 2020 |
39İzleyin | CVE-2026-11526İstismar yok | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandlerurban · gd · CWE-73 | Kritik9,8 | — | %1,4 | 14 Haz 2026 |
39İzleyin | CVE-2023-2152İstismar yok | SourceCodester Student Study Center Desk Management System index.php file inclusionoretnom23 · student study center desk management system · CWE-73 | Kritik9,8 | — | %1,2 | 18 Nis 2023 |
39İzleyin | CVE-2021-38477İstismar yok | There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulauvesy · versiondog · CWE-73 | Kritik9,8 | — | %1,2 | 22 Eki 2021 |
39İzleyin | CVE-2020-9752İstismar yok | Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through inaver · cloud explorer · CWE-73 | Kritik9,8 | — | %1,1 | 22 Mar 2020 |
39İzleyin | CVE-2023-47862İstismar yok | A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb.wwbn · avideo · CWE-73 | Kritik9,8 | — | %1,1 | 10 Oca 2024 |
39İzleyin | CVE-2023-4749İstismar yok | SourceCodester Inventory Management System index.php file inclusionmayurik · inventory management system · CWE-73 | Kritik9,8 | — | %1,0 | 3 Eyl 2023 |
- CVE-2025-3305391Hemen
Internet Shortcut Files Remote Code Execution Vulnerability
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %87microsoft · windows 10 150710 Haz 2025
- CVE-2024-4345181Hemen
NTLM Hash Disclosure Spoofing Vulnerability
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %84microsoft · windows 10 150712 Kas 2024
- CVE-2022-3995269Bu hafta
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,
KritikCVSS 9,8SilahlaştırılmışEPSS %100fortinet · fortinac16 Şub 2023
- CVE-2025-2405469Bu hafta
NTLM Hash Disclosure Spoofing Vulnerability
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %59microsoft · windows 10 150711 Mar 2025
- CVE-2024-851767Bu hafta
SPIP Bigup Multipart File Upload OS Command Injection
KritikCVSS 9,8SilahlaştırılmışEPSS %95spip · spip6 Eyl 2024
- CVE-2023-463465Bu hafta
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
KritikCVSS 9,8Kavram kanıtıEPSS %86davidlingren · media library assistant6 Eyl 2023
- CVE-2018-1724664Bu hafta
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.
KritikCVSS 9,8Kavram kanıtıEPSS %82elastic · kibana20 Ara 2018
- CVE-2023-364362Bu hafta
Boss Mini document file inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %75carel · boss mini firmware12 Tem 2023
- CVE-2025-011159Planlayın
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
YüksekCVSS 7,1KEVSilahlaştırılmışEPSS %2paloaltonetworks · pan-os12 Şub 2025
- CVE-2021-2725046Planlayın
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc0
OrtaCVSS 6,5İstismar yokEPSS %67dlink · dap-2020 firmware14 Nis 2021
- CVE-2021-2134344Planlayın
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
YüksekCVSS 7,5İstismar yokEPSS %47xstream · xstream22 Mar 2021
- CVE-2024-3714941Planlayın
GLPI allows remote code execution through the plugin loader
YüksekCVSS 8,8İstismar yokEPSS %21glpi-project · glpi10 Tem 2024
- CVE-2024-026541Planlayın
SourceCodester Clinic Queuing System GET Parameter index.php file inclusion
YüksekCVSS 8,8İstismar yokEPSS %21oretnom23 · clinic queuing system7 Oca 2024
- CVE-2024-008741Planlayın
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.
YüksekCVSS 8,8İstismar yokEPSS %20nvidia · triton inference server14 May 2024
- CVE-2025-7133840Planlayın
Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store API
KritikCVSS 10,0Kavram kanıtıEPSS %1flowiseai · flowise25 Haz 2026
- CVE-2025-5494540Planlayın
SUNNET Corporate Training Management System - External Control of File Name or Path
KritikCVSS 10,0İstismar yokEPSS %1sun.net · ehrd ctms30 Ağu 2025
- CVE-2026-2035840Planlayın
Cisco Crosswork Security Hardening Release: August 2026
KritikCVSS 10,0İstismar yokEPSS %0cisco · cisco crosswork planning19 Ağu 2026
- CVE-2025-646339İzleyin
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submiss
YüksekCVSS 8,8İstismar yokEPSS %13incsub · forminator2 Tem 2025
- CVE-2019-368139İzleyin
osc: stores downloaded (supposed) RPM in network-controlled filesystem paths
KritikCVSS 9,8İstismar yokEPSS %1suse · linux enterprise server29 Haz 2020
- CVE-2026-1152639İzleyin
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
KritikCVSS 9,8İstismar yokEPSS %1rurban · gd14 Haz 2026
- CVE-2023-215239İzleyin
SourceCodester Student Study Center Desk Management System index.php file inclusion
KritikCVSS 9,8İstismar yokEPSS %1oretnom23 · student study center desk management system18 Nis 2023
- CVE-2021-3847739İzleyin
There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipul
KritikCVSS 9,8İstismar yokEPSS %1auvesy · versiondog22 Eki 2021
- CVE-2020-975239İzleyin
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through i
KritikCVSS 9,8İstismar yokEPSS %1naver · cloud explorer22 Mar 2020
- CVE-2023-4786239İzleyin
A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb.
KritikCVSS 9,8İstismar yokEPSS %1wwbn · avideo10 Oca 2024
- CVE-2023-474939İzleyin
SourceCodester Inventory Management System index.php file inclusion
KritikCVSS 9,8İstismar yokEPSS %1mayurik · inventory management system3 Eyl 2023